DEBIAN-CVE-2026-13574

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 29 Jun 2026, 15:16
Last modified:08 Jul 2026, 04:00

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
4.8 MEDIUM
4.0 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jun 2026, 15:16
Published
Vulnerability first disclosed
08 Jul 2026, 04:00
Last Modified
Vulnerability information updated

Description

A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

CVSS Metrics

  • v4.0MEDIUMScore: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Systems

  • debianllvm-toolchain-18

    all

  • debianllvm-toolchain-19

    all | all | all | all

  • debianllvm-toolchain-21

    all

  • debianllvm-toolchain-22

    all

References (1)